GHSA-f29h-pxvx-f335

Suggest an improvement
Source
https://github.com/advisories/GHSA-f29h-pxvx-f335
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/07/GHSA-f29h-pxvx-f335/GHSA-f29h-pxvx-f335.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-f29h-pxvx-f335
Aliases
  • CVE-2025-54313
Published
2025-07-19T18:30:33Z
Modified
2025-07-22T16:23:21Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:H/A:N CVSS Calculator
Summary
eslint-config-prettier, eslint-plugin-prettier, synckit, @pkgr/core, napi-postinstall have embedded malicious code
Details

eslint-config-prettier 8.10.1, 9.1.1, 10.1.6, and 10.1.7 has embedded malicious code for a supply chain compromise. Installing an affected package executes an install.js file that launches the node-gyp.dll malware on Windows.

Database specific
{
    "github_reviewed_at": "2025-07-21T21:01:18Z",
    "severity": "HIGH",
    "cwe_ids": [
        "CWE-506"
    ],
    "nvd_published_at": "2025-07-19T17:15:23Z",
    "github_reviewed": true
}
References

Affected packages

npm

eslint-config-prettier

Package

Name
eslint-config-prettier
View open source insights on deps.dev
Purl
pkg:npm/eslint-config-prettier

Affected ranges

Type
SEMVER
Events
Introduced
8.10.1
Fixed
8.10.2

Affected versions

8.*

8.10.1

eslint-config-prettier

Package

Name
eslint-config-prettier
View open source insights on deps.dev
Purl
pkg:npm/eslint-config-prettier

Affected ranges

Type
SEMVER
Events
Introduced
9.1.1
Fixed
9.1.2

Affected versions

9.*

9.1.1

eslint-config-prettier

Package

Name
eslint-config-prettier
View open source insights on deps.dev
Purl
pkg:npm/eslint-config-prettier

Affected ranges

Type
SEMVER
Events
Introduced
10.1.6
Fixed
10.1.8

Database specific

{
    "last_known_affected_version_range": "<= 10.1.7"
}

eslint-plugin-prettier

Package

Name
eslint-plugin-prettier
View open source insights on deps.dev
Purl
pkg:npm/eslint-plugin-prettier

Affected ranges

Type
SEMVER
Events
Introduced
4.2.2
Fixed
4.2.4

Database specific

{
    "last_known_affected_version_range": "<= 4.2.3"
}

synckit

Package

Name
synckit
View open source insights on deps.dev
Purl
pkg:npm/synckit

Affected ranges

Type
SEMVER
Events
Introduced
0.11.9
Fixed
0.11.10

Affected versions

0.*

0.11.9

@pkgr/core

Package

Name
@pkgr/core
View open source insights on deps.dev
Purl
pkg:npm/%40pkgr/core

Affected ranges

Type
SEMVER
Events
Introduced
0.2.8
Fixed
0.2.9

Affected versions

0.*

0.2.8

napi-postinstall

Package

Name
napi-postinstall
View open source insights on deps.dev
Purl
pkg:npm/napi-postinstall

Affected ranges

Type
SEMVER
Events
Introduced
0.3.1
Fixed
0.3.2

Affected versions

0.*

0.3.1

got-fetch

Package

Name
got-fetch
View open source insights on deps.dev
Purl
pkg:npm/got-fetch

Affected ranges

Type
SEMVER
Events
Introduced
5.1.11
Fixed
6.0.0

Database specific

{
    "last_known_affected_version_range": "<= 5.1.12"
}